Security

How to verify a digitally signed PDF in the United States

In the US, electronic signatures are broadly valid under the federal ESIGN Act and state law, and there is no single national signature authority, so verification is about evidence, not a legal label. Check whether the PDF carries a digital signature or seal, whether it is intact and unchanged since signing, who issued the certificate, and the e-signature platform's audit trail if one was used.

4 min read

The United States has one of the most permissive legal regimes for electronic signatures in the world. That makes signing easy, and it means the burden falls on verification. A US court will look at evidence of who signed and whether the document changed, not at whether the signature met a particular technical standard.

The short answer

  • The law: the federal ESIGN Act (2000) and state laws. The Uniform Electronic Transactions Act (UETA) in almost every state, with New York having its own statute. Say a signature or contract cannot be denied legal effect solely because it is electronic. Specific exceptions exist, and consumer disclosures have extra rules.
  • No national signing authority: unlike the EU, Brazil or India, there is no single national root of trust or qualified-signature regime for private documents.
  • So verify the evidence: is there a digital signature or seal? Is it intact? Was anything added after signing? Who issued the certificate? What does the platform's audit trail show?

Step 1: check the file

Upload the PDF exactly as received to Verify PDF Signature.

  • Most US contracts are signed through e-signature platforms. The on-page signatures are usually pictures; the platform adds a digital seal to the completed file. Expect to see one signature from the platform rather than one per signer. See How to verify a DocuSign or Adobe Acrobat Sign document.
  • Signature: Valid and Unchanged since [name] signed it: the sealed content is intact.
  • Changes after signing: listed page by page, with side-by-side comparison and a download of the signed version.
  • No digital signature: a picture, typed name or scan. Legally often fine; evidentially weak. Look for other evidence.

Step 2: check the audit trail and context

Because ESIGN and UETA focus on attribution (showing the signature was the act of the person) the evidence around the signature matters:

  • The platform's certificate of completion or audit report: signer emails, timestamps, IP addresses, authentication method.
  • The communication chain: did it come from the person's known address or account?
  • For money or property: confirm by phone using a number you already had. Wire-fraud schemes in real estate and business payments rely on genuine-looking signed documents with altered payment instructions.

Documents where e-signatures may not be enough

ESIGN excludes certain documents, and state laws have their own exceptions. Commonly cited examples include wills and testamentary trusts, some family-law matters, court orders and notices, notices of cancellation of utilities or of foreclosure and eviction, and some documents required to accompany hazardous materials. Rules change and differ by state. For anything in these areas, check the current law or ask a lawyer.

Notarised documents are a separate matter. Many states now permit remote online notarisation (RON), where the notary's electronic seal and a digital certificate are applied to the PDF. You can check the notary's digital signature like any other; confirm the notary's commission with the state that issued it.

Federal documents

  • The Government Publishing Office (GPO) digitally signs many official PDF publications. Opened in Adobe, a valid GPO signature displays the "Authenticated U.S. Government Information" seal with a blue ribbon. GPO uses certification signatures, which tell you the file has not changed since GPO published it.
  • Federal employees often sign internal PDFs with certificates on their PIV or CAC cards. These chain to the Federal PKI. Outside government, computers often do not trust that chain by default, so you may see "validity unknown" in Adobe or Not trusted in general-purpose checkers. See Why Adobe says “Signature validity is unknown”.

State and professional documents

  • Professional engineers and architects in many states may seal plans with a digital signature; state licensing boards set the rules, including what makes a digital seal valid. Check the signature and changes after signing; a set of plans modified after sealing will show it.
  • Court filings increasingly use e-filing systems with their own verification; a PDF someone emails you is not the court's record.
  • Vital records and transcripts are commonly verified directly with the issuing agency or institution. See How to verify a government certificate or university degree PDF.

What "Not trusted" means in a US context

Because there is no national root, US signatures come from many authorities: commercial certificate authorities, the Federal PKI, company in-house authorities, and e-signature platforms. Some are on Adobe's approved list; many are not. Verify PDF Signature shows the Trust row separately from Signature, so an intact document signed with a company certificate reads as Signature: Valid, Trust: Not trusted: which is common and often perfectly fine.

What to keep

For anything you may have to prove later:

  • The PDF exactly as received.
  • The platform's certificate of completion or audit report.
  • A verification report: Download report (PDF) records each signature's result, every change after signing, the certificate details and the file's SHA-256 fingerprint.

Common questions

Are electronic signatures legally binding in the US?

Generally yes. The federal ESIGN Act and state laws (UETA in almost every state, with New York having its own statute) say a signature cannot be denied legal effect solely because it is electronic. Some documents, such as wills in most states, are excluded or have special rules.

Is there a US government authority that verifies digital signatures?

Not for private documents. There is no single national root or qualified-signature regime. Federal agencies use the Federal PKI internally, and the Government Publishing Office signs its official publications.

How do I verify a GPO document?

Open it in Adobe Acrobat or Reader: a valid GPO certification signature shows the “Authenticated U.S. Government Information” seal with a blue ribbon. A PDF signature checker will show whether it has changed since GPO signed it.

Why does a federal employee's signature show as “not trusted”?

PIV and CAC certificates chain to the Federal PKI, which many computers outside government do not trust by default. The signature can still be intact and genuine.

What evidence should I keep for an e-signed contract?

The file as received, the e-signature platform's audit trail or certificate of completion, and a verification report showing the signature checks and the file's SHA-256 fingerprint.